CVE-2026-29008 | U-Boot up to 2026.04-rc3 TCP_SYN_SENT handler net/tcp.c tcp_rx_state_machine offset integer underflow

SecurityVulns

A vulnerability described as very critical has been identified in U-Boot up to 2026.04-rc3. Impacted is the function tcp_rx_state_machine of the file net/tcp.c of the component TCP_SYN_SENT handler. The manipulation of the argument offset results in integer underflow.

This vulnerability is known as CVE-2026-29008. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More